Privacy Policy
Last updated: 27 August 2026
This Privacy Policy explains how Eazi-Business Limited ("Eazi-Business", "we", "our" or "us") collects, uses, shares and protects personal information when you use the Eazi-Business Partner Platform available at partners.cmslogin.io, together with related websites, applications and services that link to this policy (the "Platform").
Eazi-Business is based in the United Kingdom. This policy has been designed around the requirements of the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR. It also explains how we approach privacy rights that may apply under other laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
Different privacy laws may apply depending on where you live and how the Platform is provided to you. Where local law gives you additional mandatory rights, those rights are not affected by this policy.
1. Who we are
Eazi-Business Limited is a company registered in England and Wales under company number 08364226.
Registered office:
The Old School House
65a London Road
Oadby
Leicester
Leicestershire
LE2 5DN
United Kingdom
Privacy and data protection contact:
[email protected]
If you have a question about this policy, wish to exercise a privacy right or wish to make a data protection complaint, you can contact us using the details above.
2. Our roles
The role Eazi-Business performs under data protection law depends on the information involved and why it is being processed.
When we act as controller
We act as controller where we determine why and how personal data is processed for our own purposes.
This includes personal data used for:
- creating and administering Platform accounts;
- managing our relationship with Partners;
- billing and subscription administration;
- providing support;
- securing and monitoring the Platform;
- preventing fraud, abuse and unauthorised access;
- administering our services;
- communicating with Platform users; and
- understanding and improving the operation and performance of the Platform.
When we act as processor
Partners may upload, collect or generate personal data relating to their own customers, prospects, leads and contacts through the Platform.
For this information, the Partner will normally act as controller and Eazi-Business will act as processor on the Partner's documented instructions.
Examples include CRM records, prospect information, opportunity records, marketing activity, communications, email engagement information and customer records.
Our processing of this information is governed by our Data Processing Agreement.
If your personal data has been entered into the Platform by one of our Partners and you wish to exercise rights relating to that information, you should normally contact that Partner directly. We will assist the Partner with valid requests where required by applicable law and our Data Processing Agreement.
3. Summary of our privacy approach
We collect the information you provide to us and information reasonably required to operate and secure the Platform.
We use personal information to provide, administer, secure and improve the services you use.
We do not sell personal information.
Partner Data remains controlled by the relevant Partner where we process it on their behalf.
Connected accounts are optional and you can disconnect them.
Where required, we use recognised safeguards for international transfers of personal data.
Privacy rights vary by jurisdiction, and we honour rights that apply to our processing under applicable law.
4. Personal data we collect
Depending on how you use the Platform, we may process the following categories of personal information.
Account information
This may include:
- name;
- email address;
- account role and permissions;
- authentication information;
- hashed password information where applicable; and
- multi-factor authentication status.
Partner profile information
This may include:
- business name;
- business contact details;
- address;
- currency;
- timezone settings;
- preferences; and
- branding assets such as logos.
CRM and Partner Data
Information uploaded, entered, imported or generated by Partners may include:
- organisations;
- names and business contact information;
- email addresses;
- telephone numbers;
- notes;
- tasks;
- opportunities;
- appointment information;
- sales activity;
- prospect information; and
- customer or lead records.
Where we process this information solely on behalf of a Partner, the Partner is normally the controller and we are the processor.
Communications information
Where communication functionality is used, we may process:
- emails or other communications sent through the Platform;
- sender and recipient information;
- delivery information;
- message open or click events where enabled;
- replies;
- unsubscribe requests; and
- suppression information.
Connected account information
Where you choose to connect a third-party account, we may process authentication tokens, account identifiers and information required to provide the requested integration.
Google Calendar and Microsoft 365 are described separately in Section 8.
Authentication and security information
This may include:
- login timestamps;
- IP addresses;
- device information;
- browser and session information;
- trusted device information;
- authentication events;
- security events; and
- audit log information.
Billing information
We may process:
- subscription information;
- invoices;
- transaction records;
- billing contact information; and
- payment status.
Card payments are handled by our payment provider. We do not intentionally store full payment card numbers.
Usage and technical information
This may include:
- IP address;
- browser and device type;
- operating system;
- pages and features used;
- interaction information;
- system events;
- diagnostic data;
- performance information; and
- error logs.
5. Where personal information comes from
We may receive personal information:
- directly from you;
- from a Partner organisation that creates or administers your account;
- from other authorised users within your Partner organisation;
- from connected services that you choose to authorise;
- automatically through your use of the Platform;
- from payment and service providers; and
- from Partners who upload or generate customer, lead, prospect or contact information through the Platform.
Where a Partner provides prospect or customer information to us for processing on its behalf, that Partner is responsible for ensuring that the collection and use of the information is lawful and for providing the individual with any privacy information required by applicable law.
6. How we use personal information and our legal bases
Where the UK GDPR or EU GDPR applies, we process personal information only where an appropriate legal basis exists.
Providing and administering the Platform
We use account, profile and service information to create accounts, provide Platform functionality and manage subscriptions.
Our legal basis will normally be performance of a contract or our legitimate interests in providing the service to the organisation you represent.
Security and fraud prevention
We process authentication, technical and security information to protect accounts, investigate suspicious activity, prevent abuse and secure the Platform.
Our legal basis is normally our legitimate interests in operating a safe and secure service and, where applicable, compliance with legal obligations.
Billing and business administration
We process billing and transaction information to administer subscriptions, maintain financial records and comply with accounting and tax requirements.
Our legal bases may include performance of a contract and compliance with legal obligations.
Customer support
We process information contained in support requests where necessary to investigate and resolve issues.
Our legal basis is normally performance of a contract or our legitimate interests in supporting and improving our services.
Service improvement and analytics
We may use technical information, service performance information, diagnostic information, usage patterns and aggregated statistics to understand how the Platform operates and to improve reliability, usability and performance.
Our legal basis is normally our legitimate interests in maintaining and improving the Platform.
Where analytics or similar technologies require consent under applicable law, we will seek consent before using them.
We do not treat this legitimate interest as permission to use Partner controlled CRM content for unrelated purposes.
Connected services
Where you choose to activate an optional integration, we process the information reasonably necessary to provide that feature.
The relevant legal basis may be performance of the service requested by you, our legitimate interests in providing the requested functionality or consent where applicable law specifically requires it.
Our own marketing
Where we send communications promoting Eazi-Business services, we rely on an appropriate legal basis and comply with applicable direct marketing rules.
You may object to or unsubscribe from direct marketing at any time.
7. Partner controlled CRM, prospect and customer information
Partners may use the Platform to manage information relating to their own prospects, customers, leads and business contacts.
For this information, Eazi-Business normally acts solely on the Partner's instructions as its processor.
The Partner determines matters such as:
- which people are added to the Platform;
- where the information was obtained;
- the lawful basis relied upon;
- how long the information should be retained;
- whether marketing communications may be sent;
- the content and recipients of those communications; and
- how data subject requests should be handled.
We provide the Platform and process the information in accordance with our contract with the Partner, our Data Processing Agreement and applicable law.
8. Google Calendar, Microsoft 365 and connected accounts
The Platform may offer an optional Google Calendar integration so that Platform appointments, sessions, tasks or other supported events can be synchronised with your Google Calendar and relevant calendar information can be displayed within the Platform.
The integration is only enabled when you choose to connect your Google account and authorise the requested access.
What we access
When you connect Google Calendar, Google will display the permissions requested by the Platform.
Where the Platform requests access to Google Calendar events, this may allow the Platform to:
- create calendar events corresponding to supported Platform activities;
- update those events when information changes;
- remove those events when the relevant Platform activity is cancelled;
- check calendar information required to identify availability or conflicting events; and
- display relevant calendar events back to you within the Platform.
We use Google Calendar information only for the connected functionality that has been presented to you.
What we store
To maintain the connection, we may store:
- OAuth access tokens;
- OAuth refresh tokens;
- connected account identifiers; and
- identifiers relating to calendar events created or synchronised by the Platform.
Authentication tokens are stored using appropriate security measures and are used only to maintain the authorised connection.
Where third-party calendar events are retrieved solely for display or availability checking, we aim to minimise storage and retain only the information reasonably required to provide the feature.
Disconnecting Google Calendar
You may disconnect your Google Calendar account through your Platform settings where that option is available.
Disconnecting the integration removes our continuing authority to access the account through the stored connection and we delete or invalidate stored authentication tokens as appropriate.
You can also revoke access directly through your Google Account permissions.
Google API Limited Use
Our use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy and applicable Limited Use requirements.
We do not use Google user data obtained through restricted or sensitive API access for advertising purposes or sell that Google user data.
We only transfer Google user data where permitted by Google's applicable policies and where reasonably required to provide or secure the relevant user facing feature, comply with law or complete a permitted corporate transaction.
Human access to Google user data is restricted except where authorised by the user, reasonably necessary for security or support in circumstances permitted by Google's policies, required by law or otherwise permitted by the applicable Google API requirements.
Microsoft 365 and Outlook Calendar
The Platform may also offer an optional Microsoft 365 (Outlook) Calendar integration that works in the same way as the Google Calendar integration described above. It is only enabled when you choose to connect your Microsoft account and authorise the requested access.
When connected, the Platform may create, update and remove calendar events corresponding to supported Platform activities, check calendar information required to identify availability or conflicting events, and display relevant calendar events back to you within the Platform.
To maintain the connection we store the OAuth access and refresh tokens, connected account identifiers and event identifiers described above, using appropriate security measures, and we use this access only for the connected calendar functionality presented to you.
You may disconnect Microsoft 365 Calendar at any time through your Platform settings, which removes our continuing authority to access the account through the stored connection, and you can also revoke access directly through your Microsoft account security settings.
9. AI assisted features
Some Platform features use artificial intelligence to assist with activities such as content generation, prospect research, communication drafting, recommendations and workflow automation.
Where you use an AI assisted feature, information reasonably necessary to provide the requested functionality may be processed by Eazi-Business and contracted technology providers acting on our behalf.
Where personal data contained in Partner Data is processed through an AI service on behalf of a Partner, we process that information in accordance with our Data Processing Agreement and applicable subprocessor arrangements.
We do not sell Partner Data to AI providers.
We use reasonable measures to limit information shared with technology providers to what is necessary for the relevant functionality.
AI generated content may be inaccurate or incomplete. Our Terms of Service explain the responsibilities that apply when Partners use AI generated content or automated outreach.
10. Cookies and similar technologies
We use cookies and similar technologies where necessary to operate, authenticate and secure the Platform.
Strictly necessary technologies may be used without consent where applicable law permits this.
Where applicable law requires consent before using analytics, advertising or other non-essential technologies, we will request that consent before those technologies are activated.
You can also control certain cookie behaviour through your browser.
11. How we share personal information
We may disclose personal information to service providers and other recipients where reasonably necessary to operate the Platform or comply with law.
These may include:
- infrastructure and hosting providers;
- database and cloud service providers;
- email delivery and connected email providers;
- AI and technology service providers used to provide Platform functionality;
- calendar and connected account providers;
- payment processors;
- security, error monitoring and analytics providers;
- customer support and communications providers;
- professional advisers;
- regulators, courts, law enforcement bodies and other authorities where disclosure is required or permitted by law; and
- a purchaser, investor, successor or relevant adviser in connection with a merger, acquisition, restructuring, financing or sale of all or part of our business.
Where a service provider processes personal information on our behalf, we use contractual and other appropriate safeguards where required.
We do not sell personal information.
12. Subprocessors
Where Eazi-Business processes personal data on behalf of a Partner, we may appoint subprocessors to help provide the Platform.
Our use of subprocessors is governed by our Data Processing Agreement.
We require subprocessors to protect personal data and process it consistently with applicable contractual and legal requirements.
Where required by our Data Processing Agreement, Partners will be informed of relevant changes to subprocessors and may exercise any rights provided by that agreement.
13. International data transfers
Eazi-Business is based in the United Kingdom and uses service providers that may process personal information in the United Kingdom, the European Economic Area and other countries.
Where personal information is transferred internationally and applicable data protection law requires a transfer mechanism, we use an appropriate recognised safeguard.
Depending on the transfer, this may include:
- a finding or regulation recognising the destination as providing adequate protection;
- the European Commission Standard Contractual Clauses;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission Standard Contractual Clauses; or
- another transfer mechanism permitted by applicable law.
Where required, we also assess whether additional contractual, technical or organisational measures are appropriate to protect the information in the destination country.
International transfers of Partner controlled personal data are also governed by our Data Processing Agreement.
14. Data retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including providing the Platform, maintaining appropriate records, resolving disputes, protecting security and complying with legal obligations.
Retention periods depend on the type of information and the reason it is processed.
In general:
- account and Partner profile information is retained while the relevant account or commercial relationship remains active and for an appropriate period afterwards;
- billing and transaction records are retained for the period required by applicable accounting, tax and legal obligations;
- security and audit information is retained for an appropriate period based on security, fraud prevention and accountability requirements;
- connected account tokens are deleted or invalidated when the relevant connection is disconnected or otherwise ceases to be required;
- Partner controlled CRM, prospect and customer information is retained in accordance with the Partner's instructions, our Data Processing Agreement and the applicable subscription arrangements; and
- information may be retained for longer where necessary to establish, exercise or defend legal claims or where applicable law requires it.
When personal information is no longer required, we delete it, anonymise it or otherwise remove it from active use as appropriate.
15. Security
We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Depending on the relevant system and information, these measures may include:
- encryption in transit and at rest;
- authentication and access controls;
- tenant isolation;
- multi-factor authentication for appropriate administrative access;
- audit logging;
- security monitoring;
- restricted administrative access; and
- procedures for investigating and responding to security incidents.
No internet based service can guarantee absolute security. We continually review our security measures in light of the nature of the Platform and the risks associated with the information we process.
16. Your privacy rights
Privacy rights depend on where you live and which law applies to the relevant processing.
Where the UK GDPR or EU GDPR applies, you may have rights including:
- the right to access your personal data;
- the right to correct inaccurate personal data;
- the right to request deletion in applicable circumstances;
- the right to restrict processing;
- the right to object to processing;
- the right to object to direct marketing;
- the right to receive certain personal data in a portable format;
- the right to withdraw consent where processing is based on consent; and
- rights relating to certain forms of automated decision making.
Some rights are subject to legal conditions, exceptions and exemptions.
To exercise a right relating to personal data for which Eazi-Business is controller, contact [email protected].
Where we hold information solely as processor for one of our Partners, we may refer your request to the relevant Partner or assist that Partner in responding.
We may need to verify your identity before completing a request.
We will respond within the timeframe required by applicable law.
We will not discriminate against you for exercising an applicable privacy right.
17. Automated decision making
AI assisted features may generate content, suggestions, recommendations or workflow actions.
Unless we specifically tell you otherwise, we do not use personal data in our capacity as controller to make decisions based solely on automated processing that produce legal effects or similarly significant effects for individuals.
Where a Partner configures or uses Platform functionality involving automated processing of its own customer or prospect information, the Partner is responsible for assessing its obligations as controller.
18. California privacy rights
Where the CCPA/CPRA applies to our processing, California residents may have rights including:
- the right to know the categories and specific pieces of personal information collected about them;
- the right to know the categories of sources from which personal information is collected;
- the right to know the purposes for collecting, using, selling or sharing personal information;
- the right to know categories of third parties to whom information is disclosed;
- the right to request deletion;
- the right to correct inaccurate personal information;
- the right to opt out of the sale or sharing of personal information where applicable;
- the right to limit certain uses of sensitive personal information where applicable; and
- the right not to receive discriminatory treatment for exercising applicable rights.
The categories of personal information we collect, our sources, purposes and categories of recipients are described elsewhere in this policy.
We do not sell personal information.
If our activities amount to "sharing" for cross context behavioural advertising within the meaning of the CCPA/CPRA, we will provide any opt-out mechanism required by applicable law.
California residents may exercise applicable rights by contacting [email protected].
We may take reasonable steps to verify a request before acting on it.
19. Privacy rights in other jurisdictions
Privacy and electronic communications laws vary around the world.
If the law where you live provides additional privacy rights that apply to our processing, we will respect those rights in accordance with the applicable law.
You can contact [email protected] if you wish to exercise a right or have a question about how local privacy law applies to your information.
Where we process information solely on behalf of a Partner, the Partner remains responsible for responding as controller and we will provide assistance where required.
20. Children
The Platform is designed for business users and is not directed at children.
We do not knowingly invite anyone under the age of 16 to create or operate a Platform account.
If you believe that a child has provided personal information directly to Eazi-Business in circumstances where we act as controller, please contact us and we will investigate and take appropriate action.
Partner customers and prospects whose information is processed through the Platform remain subject to the Partner's own responsibilities as controller.
21. Data protection complaints
If you have concerns about the way Eazi-Business processes personal information for which we act as controller, you may make a data protection complaint by contacting:
Please provide enough information for us to understand the issue and identify the relevant account or processing activity.
We will acknowledge a data protection complaint within the period required by applicable law and, for complaints subject to current UK requirements, within 30 days.
We will take appropriate steps to investigate the complaint and will communicate the outcome to you without undue delay.
If we require further information in order to investigate the complaint, we may ask you to provide it.
You also have the right to raise a complaint with an applicable data protection authority.
In the United Kingdom, the supervisory authority is the Information Commissioner's Office.
You can find further information at ico.org.uk.
If you are in the European Economic Area, you may have the right to complain to the supervisory authority in the country where you live, work or where you believe an infringement occurred.
Nothing in this section prevents you from exercising any other right available under applicable law.
22. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Platform, our processing activities, technology, legal requirements or regulatory guidance.
When we make a material change, we will update the date at the top of the policy and, where appropriate or legally required, notify affected users through the Platform, by email or another appropriate method.
Where a change requires consent under applicable law, we will seek that consent before relying on it.
23. Contact us
For privacy questions, rights requests or complaints, contact:
Eazi-Business Limited
The Old School House
65a London Road
Oadby
Leicester
Leicestershire
LE2 5DN
United Kingdom
Email: [email protected]